The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

172 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 14, 2026Indexed Jul 15, 2026

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By WestJet, an Alberta Partnership (“WestJet”)

WestJet

The Office of the Privacy Commissioner of Canada (OPC) launched a Commissioner-initiated investigation (CII) into a privacy breach at WestJet that occurred on June 12, 2025. An unauthorized third party gained access to an employee's administrative account, bypassed multi-factor authentication, deployed ransomware, and exfiltrated data affecting approximately 5.1 million Canadian employees and customers. The breach exposed names, dates of birth, email addresses, mailing addresses, phone numbers, gender, travel booking information, and passport details, but no credit card numbers or SINs. WestJet took immediate containment measures, reported the breach, and provided direct and indirect notifications, credit monitoring, and identity theft protection services. WestJet has committed to further actions, including an external security assessment and providing a summary report to the OPC by August 7, 2026, to ensure the adequacy of its updated security safeguards and prevent future breaches. The CII will be discontinued upon the Commissioner being satisfied that WestJet has fulfilled all commitments.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By WestJet, an Alberta Partnership (“WestJet”)

Jul 14, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) launched a Commissioner-initiated investigation (CII) into a privacy breach at WestJet that occurred on June 12, 2025. An unauthorized third party gained access to an employee's administrative account, bypassed multi-factor authentication, deployed ransomware, and exfiltrated data affecting approximately 5.1 million Canadian employees and customers. The breach exposed names, dates of birth, email addresses, mailing addresses, phone numbers, gender, travel booking information, and passport details, but no credit card numbers or SINs. WestJet took immediate containment measures, reported the breach, and provided direct and indirect notifications, credit monitoring, and identity theft protection services. WestJet has committed to further actions, including an external security assessment and providing a summary report to the OPC by August 7, 2026, to ensure the adequacy of its updated security safeguards and prevent future breaches. The CII will be discontinued upon the Commissioner being satisfied that WestJet has fulfilled all commitments.

Key Issues
  • Adequacy of security safeguards under PIPEDA
  • Adequacy of notifications to affected individuals under PIPEDA
  • Whether WestJet's post-breach remediation actions and future commitments provide a fair and reasonable response to the incident
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 11, 2026PIPEDA Findings #2026-004Indexed Jun 30, 2026

PIPEDA Findings #2026-004: Commissioner-initiated complaints concerning X Corp.’s and X.AI LLC’s compliance with PIPEDA

X Corp. and X.AI LLC

The Office of the Privacy Commissioner of Canada (OPC) initiated complaints against X Corp. and X.AI LLC following reports that their AI chatbot, Grok, generated millions of sexualized deepfakes of identifiable individuals. The investigation focused on whether valid consent was obtained for the collection, use, and disclosure of personal information for this purpose, and if such practices were appropriate under PIPEDA. The OPC found that neither company obtained valid consent, noting the sensitive nature of the information, the unreasonableness of individuals' expectations, and the significant risk of harm. Furthermore, the OPC concluded that the generation of sexualized deepfakes was inappropriate, as the loss of privacy and harm far outweighed any benefits, and less privacy-invasive means were available. While the companies implemented some safeguards, the OPC deemed their initial response insufficient and their current measures unproven. Consequently, the matter was found well-founded, with the OPC making several recommendations for improved safeguards, proactive monitoring, and annual third-party audits, while committing to ongoing monitoring.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2026-004: Commissioner-initiated complaints concerning X Corp.’s and X.AI LLC’s compliance with PIPEDA

Jun 11, 2026PIPEDA Findings #2026-004
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated complaints against X Corp. and X.AI LLC following reports that their AI chatbot, Grok, generated millions of sexualized deepfakes of identifiable individuals. The investigation focused on whether valid consent was obtained for the collection, use, and disclosure of personal information for this purpose, and if such practices were appropriate under PIPEDA. The OPC found that neither company obtained valid consent, noting the sensitive nature of the information, the unreasonableness of individuals' expectations, and the significant risk of harm. Furthermore, the OPC concluded that the generation of sexualized deepfakes was inappropriate, as the loss of privacy and harm far outweighed any benefits, and less privacy-invasive means were available. While the companies implemented some safeguards, the OPC deemed their initial response insufficient and their current measures unproven. Consequently, the matter was found well-founded, with the OPC making several recommendations for improved safeguards, proactive monitoring, and annual third-party audits, while committing to ongoing monitoring.

Key Issues
  • Whether PIPEDA applies to X Corp. and X.AI LLC, specifically regarding the existence of a "real and substantial connection" to Canada.
  • Whether deepfakes of identifiable individuals, including sexualized deepfakes, constitute "personal information" under PIPEDA.
  • Whether X Corp. and X.AI LLC obtained valid consent for the collection, use, and disclosure of personal information to generate sexualized deepfakes, as required by Principle 4.3 of PIPEDA.
  • Whether express consent was required for the generation of sexualized deepfakes, considering the sensitivity of the information, individuals' reasonable expectations, and the risk of significant harm (Principle 4.3.4, 4.3.5, and s.6.1 of PIPEDA).
  • Whether X Corp. and X.AI LLC are accountable for ensuring valid consent for content generated by their tools in the course of commercial activity.
  • Whether a reasonable person would consider the collection, use, and disclosure of personal information for the purpose of an image generation service capable of producing sexualized deepfakes to be appropriate in the circumstances, as per subsection 5(3) of PIPEDA.
  • Whether the organizations had a legitimate need or bona fide business interest that extended to providing an image generation tool capable of producing non-consensual sexualized deepfakes.
  • Whether less privacy-invasive means were available to achieve the organizations' purposes at comparable cost and benefits.
  • Whether the loss of privacy and risk of harm associated with sexualized deepfakes were proportionate to the benefits of the practice.
  • Whether X Corp. and X.AI LLC's initial response and implemented safeguards were sufficient and effective in preventing the generation of sexualized deepfakes.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & unresolved
Federal (Canada) flag
May 6, 2026PIPEDA Findings #2026-002Indexed Jun 30, 2026

PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC

OpenAI OpCo, LLC

This joint investigation by the OPC, CAI, OIPC-BC, and OIPC-AB examined OpenAI OpCo, LLC's compliance with federal and provincial privacy laws regarding its ChatGPT service. The Offices investigated OpenAI's collection, use, and disclosure of personal information for model training, consent practices, openness, accuracy, individual rights (access, correction, deletion), data retention, and accountability. While OpenAI challenged jurisdiction and argued for implied consent, the Offices largely found contraventions in its initial practices, particularly concerning the overbroad collection of personal information from public sources and user interactions without valid consent or sufficient transparency. However, in response to the preliminary report, OpenAI committed to implementing significant privacy-enhancing measures, including a new filtering tool for training data, improved transparency, and enhanced individual rights processes. Consequently, the OPC found the matter well-founded and conditionally resolved under PIPEDA, expecting continued implementation and improvement of these measures. The OIPC-AB and OIPC-BC, due to stricter provincial consent requirements, found the consent issues well-founded and unresolved, while the CAI had mixed outcomes, also finding some issues unresolved. The Offices will monitor OpenAI's implementation of the agreed-upon recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & unresolved

PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC

May 6, 2026PIPEDA Findings #2026-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

This joint investigation by the OPC, CAI, OIPC-BC, and OIPC-AB examined OpenAI OpCo, LLC's compliance with federal and provincial privacy laws regarding its ChatGPT service. The Offices investigated OpenAI's collection, use, and disclosure of personal information for model training, consent practices, openness, accuracy, individual rights (access, correction, deletion), data retention, and accountability. While OpenAI challenged jurisdiction and argued for implied consent, the Offices largely found contraventions in its initial practices, particularly concerning the overbroad collection of personal information from public sources and user interactions without valid consent or sufficient transparency. However, in response to the preliminary report, OpenAI committed to implementing significant privacy-enhancing measures, including a new filtering tool for training data, improved transparency, and enhanced individual rights processes. Consequently, the OPC found the matter well-founded and conditionally resolved under PIPEDA, expecting continued implementation and improvement of these measures. The OIPC-AB and OIPC-BC, due to stricter provincial consent requirements, found the consent issues well-founded and unresolved, while the CAI had mixed outcomes, also finding some issues unresolved. The Offices will monitor OpenAI's implementation of the agreed-upon recommendations.

Key Issues
  • Whether the Offices had jurisdiction over OpenAI's activities under federal and provincial privacy laws.
  • Whether OpenAI collected, used, and disclosed personal information for purposes that a reasonable person would consider appropriate in the circumstances.
  • Whether OpenAI obtained valid consent for the collection and use of personal information from publicly accessible websites and licensed third-party sources for model training.
  • Whether OpenAI obtained valid consent and met its obligation to inform individuals with respect to the collection and use of personal information included in their interactions with ChatGPT.
  • Whether OpenAI obtained valid consent and met its obligation to inform individuals with respect to the disclosure of personal information collected from various sources via ChatGPT.
  • Whether OpenAI was sufficiently open and transparent about its models and information handling practices.
  • Whether OpenAI took reasonable steps to ensure that the information it generates about individuals is as accurate, complete, and up-to-date as is necessary for the purposes for which it is to be used.
  • Whether OpenAI provided individuals with the ability to obtain access to their personal information.
  • Whether OpenAI provided individuals with the ability to correct their personal information.
  • Whether OpenAI provided individuals with the ability to remove/delete their personal information from its models.
  • Whether OpenAI established appropriate retention and disposal procedures for the personal information that it collects, uses, and discloses.
  • Whether OpenAI met its accountability requirements in respect of the personal information under its control.
  • Whether the personal or domestic purposes exemption applied to OpenAI's commercial activities.
  • Whether the publicly available information exception applied to OpenAI's collection of personal information from the Internet.
  • Whether the journalistic, historical, or genealogical material exception under Quebec's Private Sector Act applied to OpenAI's model training data.
  • Whether section 9.1 of Quebec's Private Sector Act (privacy by default) applied to ChatGPT's privacy settings.
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Mar 25, 2026Indexed Jun 30, 2026

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By Nova Scotia Power

Nova Scotia Power

This document is a compliance letter from Nova Scotia Power to the OPC, outlining actions taken and commitments made following a significant data breach that occurred in March 2025. The breach, caused by malware, led to the exfiltration of personal information belonging to approximately 375,000 current and 540,000 former customers. The compromised data included names, contact information, financial details, driver's license numbers, and SINs. The OPC received numerous complaints regarding the breach, including concerns about the collection and retention of SINs and the timeliness and method of notification to affected individuals. Nova Scotia Power has committed to deleting customer SINs (subject to legal requirements) and undergoing an external security assessment by October 2026. Upon satisfactory fulfillment of these commitments, the OPC's investigation will be discontinued.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By Nova Scotia Power

Mar 25, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

This document is a compliance letter from Nova Scotia Power to the OPC, outlining actions taken and commitments made following a significant data breach that occurred in March 2025. The breach, caused by malware, led to the exfiltration of personal information belonging to approximately 375,000 current and 540,000 former customers. The compromised data included names, contact information, financial details, driver's license numbers, and SINs. The OPC received numerous complaints regarding the breach, including concerns about the collection and retention of SINs and the timeliness and method of notification to affected individuals. Nova Scotia Power has committed to deleting customer SINs (subject to legal requirements) and undergoing an external security assessment by October 2026. Upon satisfactory fulfillment of these commitments, the OPC's investigation will be discontinued.

Key Issues
  • Whether Nova Scotia Power's security safeguards were adequate to protect personal information
  • Whether Nova Scotia Power's collection and retention of Social Insurance Numbers (SINs) was appropriate
  • Whether Nova Scotia Power's notification of affected individuals was timely and appropriate
  • Whether Nova Scotia Power has taken sufficient corrective measures to address the breach and prevent future incidents
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Mar 17, 2026Indexed Jun 30, 2026

Compliance agreement between the Privacy Commissioner of Canada and the World Anti-Doping Agency

World Anti-Doping Agency (WADA)

The World Anti-Doping Agency (WADA) entered into a compliance agreement with the Privacy Commissioner of Canada (OPC) to resolve an investigation into WADA's collection, use, and disclosure practices concerning athletes' personal information in its Anti-Doping Administration and Management System (ADAMS). The OPC launched an investigation after receiving a complaint, and WADA disputed the allegations and challenged the OPC's jurisdiction in Federal Court. Without admitting contravention or waiving jurisdictional rights, WADA agreed to remedial measures. These measures include ceasing to permit Anti-Doping Organizations (ADOs) to use ADAMS data for non-anti-doping purposes, updating the World Anti-Doping Code, and amending agreements with ADOs to restrict data use to anti-doping purposes only. WADA will also provide the OPC with a mechanism to ensure ADOs adhere to these restrictions. The investigation will be placed in abeyance and discontinued upon completion of the remedial measures.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Compliance agreement between the Privacy Commissioner of Canada and the World Anti-Doping Agency

Mar 17, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The World Anti-Doping Agency (WADA) entered into a compliance agreement with the Privacy Commissioner of Canada (OPC) to resolve an investigation into WADA's collection, use, and disclosure practices concerning athletes' personal information in its Anti-Doping Administration and Management System (ADAMS). The OPC launched an investigation after receiving a complaint, and WADA disputed the allegations and challenged the OPC's jurisdiction in Federal Court. Without admitting contravention or waiving jurisdictional rights, WADA agreed to remedial measures. These measures include ceasing to permit Anti-Doping Organizations (ADOs) to use ADAMS data for non-anti-doping purposes, updating the World Anti-Doping Code, and amending agreements with ADOs to restrict data use to anti-doping purposes only. WADA will also provide the OPC with a mechanism to ensure ADOs adhere to these restrictions. The investigation will be placed in abeyance and discontinued upon completion of the remedial measures.

Key Issues
  • Whether WADA's collection, use, and disclosure practices of athletes' personal information in ADAMS comply with PIPEDA
  • Whether the OPC has statutory, territorial, and/or subject matter jurisdiction over WADA
  • Whether ADOs are permitted to use personal information in ADAMS for purposes other than anti-doping
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 5, 2026PIPEDA Findings #2026-001Indexed Jun 30, 2026

PIPEDA Findings #2026-001: Investigation into the personal information retention practices of Loblaw for the PC Optimum Loyalty Program

Loblaw Companies Ltd.

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Loblaw Companies Ltd. (Loblaw) regarding its PC Optimum Loyalty Program, focusing on the handling of privacy challenges and the retention of personal information. The investigation found that Loblaw contravened PIPEDA Principle 4.10 by failing to adequately address privacy challenges and respond to account deletion requests in a timely manner, though this issue was resolved during the investigation as Loblaw enhanced its procedures. The OPC also found that Loblaw contravened PIPEDA Principle 4.5.3 by not sufficiently anonymizing personal information retained from closed PC Optimum accounts, meaning there was a serious possibility of re-identification. Loblaw disagreed with this finding but agreed to engage an independent third party to assess its anonymization process and implement recommendations. A preliminary matter regarding requiring physical card holders to create an online account for deletion was found not well-founded. The overall outcome reflects a mix of resolved and conditionally resolved well-founded findings.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2026-001: Investigation into the personal information retention practices of Loblaw for the PC Optimum Loyalty Program

Mar 5, 2026PIPEDA Findings #2026-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Loblaw Companies Ltd. (Loblaw) regarding its PC Optimum Loyalty Program, focusing on the handling of privacy challenges and the retention of personal information. The investigation found that Loblaw contravened PIPEDA Principle 4.10 by failing to adequately address privacy challenges and respond to account deletion requests in a timely manner, though this issue was resolved during the investigation as Loblaw enhanced its procedures. The OPC also found that Loblaw contravened PIPEDA Principle 4.5.3 by not sufficiently anonymizing personal information retained from closed PC Optimum accounts, meaning there was a serious possibility of re-identification. Loblaw disagreed with this finding but agreed to engage an independent third party to assess its anonymization process and implement recommendations. A preliminary matter regarding requiring physical card holders to create an online account for deletion was found not well-founded. The overall outcome reflects a mix of resolved and conditionally resolved well-founded findings.

Key Issues
  • Whether Loblaw adequately addresses privacy challenges raised by individuals concerning account deletion (PIPEDA Principle 4.10)
  • Whether Loblaw retains personal information of PC Optimum members for longer than necessary after account closure (PIPEDA Principle 4.5.3)
  • Whether Loblaw collected unnecessary personal information by requiring physical card holders to create an online account to delete their PC Optimum account (PIPEDA Principle 4.4)
  • Whether Loblaw established retention schedules for customer support logs (PIPEDA Principle 4.5.2)
  • Whether Loblaw retains universal login credentials (PCids) for longer than necessary for members with no other associated accounts (PIPEDA Principle 4.5.3)
  • Whether Loblaw's anonymization process for retained Historical Transaction Data, Loyalty Data, and Usage Data ensures no serious possibility of re-identification
  • Whether Loblaw's retention of public IP address data after account closure is sufficiently anonymized
  • Whether Loblaw's practice of retaining email domain portions after account closure is sufficiently anonymized
  • Whether manual processing errors in Loblaw's de-identification process were adequately detected and addressed
  • Whether Loblaw ensured identifiers were removed from back-up systems as part of its anonymization process
  • Whether Loblaw considered the impact of other factors affecting re-identification risk, such as separately retained PCid data
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jan 9, 2026PIPEDA Findings #2026-003Indexed Jun 30, 2026

PIPEDA Findings #2026-003: Investigation into Bell’s compliance with PIPEDA when responding to an access request for personal information

Bell Canada

The complainant alleged that Bell Canada contravened PIPEDA by failing to respond to an access request within 30 days and by denying access to his cellphone logs. The OPC found that Bell contravened subsection 8(3) of PIPEDA for the delayed response and Principle 4.9 for denying access, as the phone logs constituted the complainant's personal information. The OPC determined that the complainant's privacy interest in his phone logs outweighed the ex-spouse's interest, and there was a public interest in disclosure. Bell agreed to provide the requested logs to the complainant, resolving that aspect of the complaint. Bell also committed to implementing recommendations to improve its access request procedures and enhance openness regarding data access on shared accounts, leading to a conditionally resolved outcome for these issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2026-003: Investigation into Bell’s compliance with PIPEDA when responding to an access request for personal information

Jan 9, 2026PIPEDA Findings #2026-003
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Bell Canada contravened PIPEDA by failing to respond to an access request within 30 days and by denying access to his cellphone logs. The OPC found that Bell contravened subsection 8(3) of PIPEDA for the delayed response and Principle 4.9 for denying access, as the phone logs constituted the complainant's personal information. The OPC determined that the complainant's privacy interest in his phone logs outweighed the ex-spouse's interest, and there was a public interest in disclosure. Bell agreed to provide the requested logs to the complainant, resolving that aspect of the complaint. Bell also committed to implementing recommendations to improve its access request procedures and enhance openness regarding data access on shared accounts, leading to a conditionally resolved outcome for these issues.

Key Issues
  • Whether Bell responded to the Complainant’s access request within thirty days as per subsection 8(3) of PIPEDA
  • Whether Bell adequately responded to the Complainant’s request to access his personal information under Principle 4.9 of PIPEDA
  • Whether phone logs relating to a specific phoneline constitute the personal information of the phoneline's user, even if they are not the account holder
  • Whether the Complainant's interest in accessing the phone logs is greater than the ex-spouse's interest in non-disclosure of the phone logs
  • Whether Bell was sufficiently open with individuals about account holders' access to phone usage details on shared accounts, contrary to PIPEDA's Openness principle (Principle 4.8.1)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 1, 2025PIPEDA Findings #2025-004Indexed Jun 30, 2026

PIPEDA Findings #2025-004: Investigation into the privacy practices of Staples Canada ULC related to electronic devices to be resold as part of its Openbox program

Staples Canada ULC

A former employee complained that Staples Canada ULC (Staples) failed to adequately protect and remove personal information from returned laptops before reselling them through its Openbox program. The complainant alleged that Staples lacked adequate internal policies, processes, and training for staff to wipe data from these devices. The OPC's investigation found deficiencies in Staples' policies, procedures, and training, and that employees did not consistently follow manufacturer guidelines for data wiping, leading to residual personal information on 23% of sampled devices. Staples agreed to implement recommendations to improve its data wiping procedures, training, and to arrange for independent third-party spot checks. The OPC concluded that Staples contravened PIPEDA Principles 4.7.1 and 4.7.3.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2025-004: Investigation into the privacy practices of Staples Canada ULC related to electronic devices to be resold as part of its Openbox program

Dec 1, 2025PIPEDA Findings #2025-004
Adjudicator: Philippe Dufresne
Plain-Language Summary

A former employee complained that Staples Canada ULC (Staples) failed to adequately protect and remove personal information from returned laptops before reselling them through its Openbox program. The complainant alleged that Staples lacked adequate internal policies, processes, and training for staff to wipe data from these devices. The OPC's investigation found deficiencies in Staples' policies, procedures, and training, and that employees did not consistently follow manufacturer guidelines for data wiping, leading to residual personal information on 23% of sampled devices. Staples agreed to implement recommendations to improve its data wiping procedures, training, and to arrange for independent third-party spot checks. The OPC concluded that Staples contravened PIPEDA Principles 4.7.1 and 4.7.3.

Key Issues
  • Whether Staples had adequate security safeguards to protect personal information on returned laptops under Principle 4.7.1 PIPEDA
  • Whether Staples' methods of protection included adequate physical, organizational, and technological measures under Principle 4.7.3 PIPEDA
  • Whether Staples' internal policies and procedures for data wiping were clear and consistent
  • Whether Staples provided adequate training to employees responsible for wiping data from returned devices
  • Whether Staples consistently performed full data wipes according to manufacturer instructions on returned laptops
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Nov 25, 2025PIPEDA Findings #2025-005Indexed Jun 30, 2026

PIPEDA Findings #2025-005: Investigation into a swimming pool’s compliance with consent requirements under the Personal Information Protection and Electronic Documents Act

A privately owned swimming pool

An individual complained that a private swimming pool required parents to consent to the use of their children's photos and videos for promotional purposes as a condition of service for swimming lessons. The complainant argued this violated PIPEDA's consent requirements, specifically Principle 4.3.3, which prohibits requiring consent for information beyond what is necessary for the service. The swimming pool contended that the photo policy was a reasonable business need for promotion and staff training, and that tracking individual consent would be burdensome. The OPC found that images of children in swim attire are sensitive personal information and that requiring consent for promotional photos and staff training videos was not strictly necessary for providing swimming lessons. The OPC concluded that this practice contravened PIPEDA Principles 4.3.3 and 4.3.6. The complaint was found to be well-founded and resolved after the swimming pool agreed to implement an opt-in photo policy.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2025-005: Investigation into a swimming pool’s compliance with consent requirements under the Personal Information Protection and Electronic Documents Act

Nov 25, 2025PIPEDA Findings #2025-005
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that a private swimming pool required parents to consent to the use of their children's photos and videos for promotional purposes as a condition of service for swimming lessons. The complainant argued this violated PIPEDA's consent requirements, specifically Principle 4.3.3, which prohibits requiring consent for information beyond what is necessary for the service. The swimming pool contended that the photo policy was a reasonable business need for promotion and staff training, and that tracking individual consent would be burdensome. The OPC found that images of children in swim attire are sensitive personal information and that requiring consent for promotional photos and staff training videos was not strictly necessary for providing swimming lessons. The OPC concluded that this practice contravened PIPEDA Principles 4.3.3 and 4.3.6. The complaint was found to be well-founded and resolved after the swimming pool agreed to implement an opt-in photo policy.

Key Issues
  • Whether requiring consent for promotional photos and videos of children as a condition of service for swimming lessons contravenes Principle 4.3.3 of PIPEDA
  • Whether images of children in swim attire constitute sensitive personal information
  • Whether the collection, use, or disclosure of images for promotional or staff training purposes is strictly necessary for the provision of swimming lessons
  • Whether the organization offered individuals a choice regarding the collection, use, or disclosure of images for promotional or staff training purposes
  • Whether the organization should have sought express consent for the collection, use, or disclosure of images of children
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Sep 23, 2025PIPEDA Findings #2025-003Indexed Jun 30, 2026

PIPEDA Findings #2025-003: Joint investigation of TikTok Pte. Ltd. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Office of the Information and Privacy Commissioner for British Columbia, and the Office of the Information and Privacy Commissioner of Alberta

TikTok Pte. Ltd.

A joint investigation by the Office of the Privacy Commissioner of Canada (OPC) and provincial privacy regulators (CAI, OIPC BC, OIPC AB) examined TikTok Pte. Ltd.'s compliance with federal and provincial private sector privacy laws. The investigation focused on TikTok's collection, use, and disclosure of personal information for ad targeting and content personalization, with a particular emphasis on practices affecting children. The Offices found that TikTok's age assurance measures were inadequate, leading to the collection and use of sensitive personal information from a large number of underage users for purposes deemed inappropriate. Furthermore, TikTok failed to obtain valid and meaningful consent from both adult and youth users due to unclear, inaccessible, and incomplete privacy communications, including regarding biometric information and cross-border data transfers. The CAI specifically identified contraventions related to Quebec's transparency and privacy-by-default obligations. While TikTok disagreed with the findings, it committed to implementing enhanced age assurance mechanisms, improving privacy communications, and limiting ad targeting for under-18 users. The Offices concluded the matter as well-founded and conditionally resolved, contingent on TikTok's satisfactory implementation of these significant commitments.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2025-003: Joint investigation of TikTok Pte. Ltd. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Office of the Information and Privacy Commissioner for British Columbia, and the Office of the Information and Privacy Commissioner of Alberta

Sep 23, 2025PIPEDA Findings #2025-003
Adjudicator: Philippe Dufresne
Plain-Language Summary

A joint investigation by the Office of the Privacy Commissioner of Canada (OPC) and provincial privacy regulators (CAI, OIPC BC, OIPC AB) examined TikTok Pte. Ltd.'s compliance with federal and provincial private sector privacy laws. The investigation focused on TikTok's collection, use, and disclosure of personal information for ad targeting and content personalization, with a particular emphasis on practices affecting children. The Offices found that TikTok's age assurance measures were inadequate, leading to the collection and use of sensitive personal information from a large number of underage users for purposes deemed inappropriate. Furthermore, TikTok failed to obtain valid and meaningful consent from both adult and youth users due to unclear, inaccessible, and incomplete privacy communications, including regarding biometric information and cross-border data transfers. The CAI specifically identified contraventions related to Quebec's transparency and privacy-by-default obligations. While TikTok disagreed with the findings, it committed to implementing enhanced age assurance mechanisms, improving privacy communications, and limiting ad targeting for under-18 users. The Offices concluded the matter as well-founded and conditionally resolved, contingent on TikTok's satisfactory implementation of these significant commitments.

Key Issues
  • Whether TikTok was collecting, using, and disclosing personal information, particularly with respect to children, for an appropriate, reasonable, and legitimate purpose.
  • Whether TikTok's age assurance mechanisms were effective in preventing underage users from accessing the platform.
  • Whether TikTok obtained valid and meaningful consent from its users for tracking, profiling, targeting, and content personalization.
  • Whether TikTok's privacy communications provided sufficient upfront, clear, and comprehensive information to adult users to ensure meaningful consent.
  • Whether TikTok adequately explained its collection and use of users' biometric information to ensure meaningful consent.
  • Whether TikTok's privacy communications were adequate to obtain meaningful consent from youth (13-17), considering their cognitive development and potential harms from targeted ads.
  • Whether TikTok met its obligations under Quebec's Private Sector Act to inform persons concerned about the collection and use of personal information for user profiles, ad targeting, and content personalization.
  • Whether TikTok ensured that privacy settings provided the highest level of privacy by default under Quebec's Private Sector Act.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Aug 27, 2025PIPEDA Findings #2025-002Indexed Jun 30, 2026

PIPEDA Findings #2025-002: Investigation and recommendations concerning Google search engine service’s compliance with its obligations under PIPEDA

Google LLC

The OPC investigated a complaint against Google regarding its search engine displaying outdated media articles about the Complainant's HIV status and a stayed criminal charge when their name was searched. The Complainant alleged these articles caused significant harm, including physical assault and lost employment, and sought their de-listing from name-based search results. The OPC's jurisdiction over Google's search engine under PIPEDA was affirmed by the Federal Court and Federal Court of Appeal, rejecting Google's claims of non-commercial activity and journalistic exemption. The OPC found Google did not contravene Principle 4.6 (accuracy), as its responsibility was for the search results accurately reflecting linked content, not the content itself. However, the OPC concluded that Google contravened subsection 5(3) (appropriate purposes), determining that the significant harms to the Complainant's safety and dignity outweighed the limited public interest in the articles remaining linked to their name. The OPC recommended Google de-list the articles from searches for the Complainant's name, balancing privacy rights with freedom of expression. Google declined to implement this recommendation, stating it required further court guidance on the "right to de-listing" and Charter implications. Consequently, the complaint was found well-founded and unresolved regarding subsection 5(3), and not well-founded for the accuracy issue.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2025-002: Investigation and recommendations concerning Google search engine service’s compliance with its obligations under PIPEDA

Aug 27, 2025PIPEDA Findings #2025-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

The OPC investigated a complaint against Google regarding its search engine displaying outdated media articles about the Complainant's HIV status and a stayed criminal charge when their name was searched. The Complainant alleged these articles caused significant harm, including physical assault and lost employment, and sought their de-listing from name-based search results. The OPC's jurisdiction over Google's search engine under PIPEDA was affirmed by the Federal Court and Federal Court of Appeal, rejecting Google's claims of non-commercial activity and journalistic exemption. The OPC found Google did not contravene Principle 4.6 (accuracy), as its responsibility was for the search results accurately reflecting linked content, not the content itself. However, the OPC concluded that Google contravened subsection 5(3) (appropriate purposes), determining that the significant harms to the Complainant's safety and dignity outweighed the limited public interest in the articles remaining linked to their name. The OPC recommended Google de-list the articles from searches for the Complainant's name, balancing privacy rights with freedom of expression. Google declined to implement this recommendation, stating it required further court guidance on the "right to de-listing" and Charter implications. Consequently, the complaint was found well-founded and unresolved regarding subsection 5(3), and not well-founded for the accuracy issue.

Key Issues
  • Whether PIPEDA applies to Google's search engine service as a commercial activity within the meaning of paragraph 4(1)(a) of PIPEDA
  • Whether the operation of Google’s search engine service is excluded from the application of Part 1 of PIPEDA by virtue of paragraph 4(2)(c) of PIPEDA because it involves the collection, use or disclosure of personal information for journalistic, artistic or literary purposes and for no other purpose
  • Whether Google is contravening Accuracy requirements under Principle 4.6 of Schedule 1 of PIPEDA by continuing to display the search results in response to searches for the Complainant’s name
  • Whether Google is contravening subsection 5(3) of PIPEDA by continuing to display the search results in response to searches for the Complainant’s name, considering whether the purposes are appropriate in the circumstances
  • Whether the accessibility of information in response to a search for the Complainant's name causes significant harm to the Complainant
  • Whether the significant harm to the Complainant outweighs the public interest in the search results remaining available through Google's search engine by searching the Complainant's name
  • Whether Google collected, used, or disclosed personal information without consent under Principles 4.3.4 and 4.3.8 of Schedule 1 of PIPEDA (OPC declined to address)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jun 20, 2025PIPEDA Findings #2025-001Indexed Jun 30, 2026

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

23andMe Inc.

The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

Jun 20, 2025PIPEDA Findings #2025-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.

Key Issues
  • Whether 23andMe had appropriate safeguards to protect highly sensitive personal information under its control, specifically against credential stuffing attacks.
  • Whether 23andMe's prevention measures, including mandatory Multi-factor Authentication (MFA), compromised-password checks, and minimum password requirements, were adequate.
  • Whether 23andMe's detection measures, including detection systems, digital fingerprinting, and device history, were adequate to identify ongoing attacks.
  • Whether 23andMe adequately investigated anomalies and claims of breach prior to public disclosure.
  • Whether 23andMe's breach response, including the timeliness of disabling active user sessions, disabling raw DNA download features, and implementing mandatory MFA, was adequate.
  • Whether 23andMe adequately notified the OPC about the breach, including the completeness of information provided and timeliness.
  • Whether 23andMe adequately notified affected individuals about the breach, including the completeness of information provided and timeliness.
  • Whether the data breach created a real risk of significant harm to affected individuals, triggering notification obligations.
  • Whether 23andMe's methodology for identifying and notifying individuals whose raw DNA was downloaded by the Threat Actor was adequate.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 28, 2024PIPEDA Findings #2024-002Indexed Jun 30, 2026

PIPEDA Findings #2024-002: Investigation into Brinks Home

Brinks Home

A Brinks Home customer complained that he could view other customers' personal information through his online portal. The OPC investigated whether Brinks Home had adequate security safeguards and complied with breach notification requirements. Brinks Home acknowledged an employee error caused 3,340 customer records to be accessible to 102 other customers, with up to 20 potentially accessing the data. The OPC found that Brinks Home failed to adequately protect personal information, but this issue was resolved by the company's corrective actions and subsequent sale of its Canadian customer accounts. Regarding breach notification, the OPC determined that while the information was sensitive, the probability of misuse was low because the unauthorized access was by known customers, not malicious actors. Therefore, the incident did not pose a real risk of significant harm, and Brinks Home was not required to report it or notify affected individuals.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2024-002: Investigation into Brinks Home

Mar 28, 2024PIPEDA Findings #2024-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

A Brinks Home customer complained that he could view other customers' personal information through his online portal. The OPC investigated whether Brinks Home had adequate security safeguards and complied with breach notification requirements. Brinks Home acknowledged an employee error caused 3,340 customer records to be accessible to 102 other customers, with up to 20 potentially accessing the data. The OPC found that Brinks Home failed to adequately protect personal information, but this issue was resolved by the company's corrective actions and subsequent sale of its Canadian customer accounts. Regarding breach notification, the OPC determined that while the information was sensitive, the probability of misuse was low because the unauthorized access was by known customers, not malicious actors. Therefore, the incident did not pose a real risk of significant harm, and Brinks Home was not required to report it or notify affected individuals.

Key Issues
  • Whether Brinks Home implemented adequate security safeguards to protect customers' personal information under Principle 4.7 of Schedule 1 of PIPEDA
  • Whether Brinks Home complied with breach notification requirements under section 10.1 of PIPEDA
  • Whether the breach presented a real risk of significant harm (RROSH)
  • Whether the personal information involved was sensitive
  • Whether the probability of misuse of the personal information was low
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Feb 29, 2024PIPEDA Findings #2024-001Indexed Jun 30, 2026

PIPEDA Findings #2024-001: Investigation into Aylo (formerly MindGeek)’s Compliance with PIPEDA

Aylo (formerly MindGeek)

The OPC investigated Aylo (formerly MindGeek), a global technology company operating major pornographic websites like Pornhub, following a complaint from an individual whose intimate video was uploaded without her consent. The investigation focused on MindGeek's compliance with PIPEDA regarding consent for personal information collection, its content takedown process, and overall accountability. The OPC found that MindGeek failed to obtain valid and meaningful express consent directly from individuals depicted in highly sensitive content, relying instead on uploaders, which was deemed insufficient. MindGeek's content takedown process was also found to be not easily accessible, simple-to-use, or effective for individuals seeking removal of non-consensual content. These deficiencies demonstrated a broader lack of accountability for the vast amount of sensitive personal information under MindGeek's control. MindGeek disagreed with the findings and did not commit to implementing the OPC's recommendations, which included ceasing uploads without direct consent, deleting non-consensual content, and establishing a privacy management program. Consequently, the complaint was found to be well-founded and unresolved, with the OPC issuing several recommendations for compliance and independent oversight.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2024-001: Investigation into Aylo (formerly MindGeek)’s Compliance with PIPEDA

Feb 29, 2024PIPEDA Findings #2024-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The OPC investigated Aylo (formerly MindGeek), a global technology company operating major pornographic websites like Pornhub, following a complaint from an individual whose intimate video was uploaded without her consent. The investigation focused on MindGeek's compliance with PIPEDA regarding consent for personal information collection, its content takedown process, and overall accountability. The OPC found that MindGeek failed to obtain valid and meaningful express consent directly from individuals depicted in highly sensitive content, relying instead on uploaders, which was deemed insufficient. MindGeek's content takedown process was also found to be not easily accessible, simple-to-use, or effective for individuals seeking removal of non-consensual content. These deficiencies demonstrated a broader lack of accountability for the vast amount of sensitive personal information under MindGeek's control. MindGeek disagreed with the findings and did not commit to implementing the OPC's recommendations, which included ceasing uploads without direct consent, deleting non-consensual content, and establishing a privacy management program. Consequently, the complaint was found to be well-founded and unresolved, with the OPC issuing several recommendations for compliance and independent oversight.

Key Issues
  • Whether PIPEDA applied to MindGeek given its international operations but significant Canadian connection.
  • Whether MindGeek obtained valid and meaningful consent for the collection, use, and disclosure of highly sensitive personal information (intimate images and associated identifiers) of individuals depicted in content uploaded to its websites, as required by Principle 4.3 and s. 6.1 of PIPEDA.
  • Whether MindGeek's reliance on uploaders to attest consent constituted reasonable efforts to ensure meaningful consent.
  • Whether MindGeek's "enhanced" consent practices implemented in 2020 remedied the contravention of consent requirements.
  • Whether MindGeek provided individuals with an easily accessible, simple-to-use, and effective process for having their personal information removed from its websites, as required by Principles 4.10 and 4.10.2 of PIPEDA.
  • Whether MindGeek's takedown process was effective at preventing further uploads of the same or other content depicting the requester.
  • Whether MindGeek was accountable for the personal information under its control, as required by Principle 4.1 of Schedule 1 of PIPEDA.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 31, 2023PIPEDA Findings #2023-002Indexed Jun 30, 2026

PIPEDA Findings #2023-002: Investigation into Agronomy’s privacy practices related to safeguards, accountability valid consent for the collection and use of personal information

Agronomy Company of Canada Ltd.

The Office of the Privacy Commissioner of Canada (OPC) investigated Agronomy Company of Canada Ltd. following a complaint alleging inadequate safeguards, lack of accountability, and invalid consent for personal information collection and use, stemming from a data breach. A malicious actor gained access to Agronomy's systems, exfiltrating sensitive personal information of 845 individuals, including SINs, financial details, and identification documents, before deploying ransomware. The OPC found Agronomy failed to implement appropriate safeguards, citing a lack of multifactor authentication, network segregation, data encryption, and detection tools, which contributed to the breach. Furthermore, Agronomy lacked a comprehensive privacy policy, a designated privacy officer, and adequate staff training, indicating a failure in accountability. While these two aspects were found well-founded, Agronomy committed to significant improvements, leading to a conditionally resolved outcome. However, the OPC found the complaint regarding invalid consent for credit services not well-founded, as the complainant had signed a clearly labelled credit application and utilized the extended credit.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2023-002: Investigation into Agronomy’s privacy practices related to safeguards, accountability valid consent for the collection and use of personal information

Jul 31, 2023PIPEDA Findings #2023-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated Agronomy Company of Canada Ltd. following a complaint alleging inadequate safeguards, lack of accountability, and invalid consent for personal information collection and use, stemming from a data breach. A malicious actor gained access to Agronomy's systems, exfiltrating sensitive personal information of 845 individuals, including SINs, financial details, and identification documents, before deploying ransomware. The OPC found Agronomy failed to implement appropriate safeguards, citing a lack of multifactor authentication, network segregation, data encryption, and detection tools, which contributed to the breach. Furthermore, Agronomy lacked a comprehensive privacy policy, a designated privacy officer, and adequate staff training, indicating a failure in accountability. While these two aspects were found well-founded, Agronomy committed to significant improvements, leading to a conditionally resolved outcome. However, the OPC found the complaint regarding invalid consent for credit services not well-founded, as the complainant had signed a clearly labelled credit application and utilized the extended credit.

Key Issues
  • Whether Agronomy implemented appropriate safeguards to adequately protect personal information under its control, as per PIPEDA Principle 4.7.
  • Whether Agronomy's technical safeguards (multifactor authentication, network segregation, data encryption, detection and response tools) were appropriate for the sensitivity of the information.
  • Whether Agronomy's organizational safeguards (incident response protocols, information management, security documentation, staff training) were adequate.
  • Whether Agronomy was accountable for personal information under its control, including designating an individual for PIPEDA compliance and implementing policies and practices, as per PIPEDA Principle 4.1.
  • Whether Agronomy obtained valid and meaningful consent for the collection and use of personal information for credit services, particularly sensitive information, as per PIPEDA Principle 4.3.